Best Of
Zyxel Launches Astra Endpoint Security to Protect Hybrid SMBs
As the boom in flexible working practices enables employees to connect and collaborate from anywhere, SMBs need to support more roaming users and additional devices that need to connect to branch offices and cloud-based apps. We have released the official cloud-based endpoint security service-Zyxel Astra, providing you a protective bubble to roaming employees with the ability to monitor and secure all endpoints through one portal.
Extend Endpoints Protection on All Your Platforms
Astra is now supported across all major operating systems including iOS, Android, Mac, Windows (Q2, 2023) to protect your endpoints on all platforms.
Help your team achieve both security and efficiency without the technical complexities.
Join the Astra service for a FREE TRIAL now through Astra Portal
and get started with app: App Store & Google Play
The license service is now also available to purchase!
Zywall USG FLEX Series, ATP Series & VPN Series - V5.35 Firmware Release
Zywall USG FLEX Series, ATP Series & VPN Series Release Note Jan, 2023
Firmware Version on all models
USG FLEX | ATP | VPN | |||
USG FLEX 50 | V5.35(ABAQ.0) | ATP100 | V5.35(ABPS.0) | VPN50 | V5.35(ABHL.0) |
USG FLEX 50W | V5.35(ABAR.0) | ATP100W | V5.35(ABRW.0) | VPN100 | V5.35(ABFV.0) |
USG FLEX 100 | V5.35(ABUH.0) | ATP200 | V5.35(ABFW.0) | VPN300 | V5.35(ABFC.0) |
USG FLEX 100W | V5.35(ABWC.0) | ATP500 | V5.35(ABFU.0) | VPN1000 | V5.35(ABIP.0) |
USG FLEX 200 | V5.35(ABUI.0) | ATP700 | V5.35(ABTJ.0) | ||
USG FLEX 500 | V5.35(ABUJ.0) | ATP800 | V5.35(ABIQ.0) | ||
USG FLEX 700 | V5.35(ABWD.0) |
New Feature and Enhancements
No. | Enhancement | CLD | STD |
1. | Configuration files download with password protection | V | |
2. | Custom DDNS support auto update when public IP changed | V | |
3. | Automatically update DDNS IP address at DDNS monitor page | V | |
4. | System Log support DHCP IP conflict detection | V | |
5. | Support traffic log rotate on USB storage | V | |
6. | Support Sensitive Data Protection to protect management password | V | |
7. | [AP Controller] Update AP images V6.45(.0) | V | |
8. | [AP Controller] DCS Client Aware default setting changed to disable. | V | |
9. | [AP Controller] DFS channel behavior enhance for better UX. | V | |
10. | [AP Controller] APC changed multicast to unicast default setting. | V | |
11. | [AP Controller] Refine default AMPDU size. | V | |
12. | [AP Controller] Support WiFi6E settings on APC. | V | |
13. | [AP Controller] Support WAX655E Ethernet setting. | V | |
14. | [AP Controller] Hostname supported in wireless station info. | V | |
15. | [AP Controller] CAPWAP online/offline does not kick STA. | V | |
16. | [AP Controller] Top-N supports 6GHz radio information. | V | |
17. | [AP Controller] ZLD 5.3x APC fully support WiFi6E AP. | V | |
18. | [AP Controller] ZyMesh support WiFi 6E (6GHz). | V | |
19. | [Feature Change] [eITS#220600529] Response Message remove customization page layout change to default block page design. | V | |
20. | [Feature Change] The default radio profile under AP controller in Wireless setup wizard change from 11ac to 11ax | V | |
21. | [Feature Change] Modify the wording at 5G Radio page: a. Change the wording “Enable 5 GHz DFS Aware” to “Avoid 5 GHz DFS Channel” | V | |
22. | Support captive portal logout via 6.6.6.6 | V | |
23. | SecuReporter traffic log support client MAC address | V | |
24. | Event Log support DHCP IP conflict detection | V |
Bug Fix
CLD=Cloud mode, STD=Standalone mode
No. | Bug Fix | CLD | STD |
1. | eITS#221000888 / 221200149 a. Fix: The device stops sending SMS via a SMS gateway after several days and also becomes unresponsive. | V | |
2. | eITS#221001336 a. Fix: In the policy route rule, select interface/gateway as the next hop and enable connectivity check. After you change the next hop from interface/gateway to trunk, connectivity check becomes greyed out but the previous connectivity check settings are still applied to the policy route rule. | V | |
3. | eITS#221100576 a. Fix: USG FLEX 50 virtual device in the dashboard is incorrect | V | |
4. | eITS# 221100935 a. Fix: Support fast recovery | V | |
5. | eITS# 221101130 a. Fix: the boot up console warning message and SYS red light issue. | V | |
6. | eITS# 221101139 a. Fix: Security policy is not working when 2FA is enabled | V | |
7. | eITS#221101280 a. Fix: NAT port forwarding data transfer rate is unstable | V | |
8. | eITS#221101428 a. Fix: Since the device is upgraded to firmware to V5.32, the warning message “Unverified Firmware Installed” pops up in the dashboard. | V | |
9. | eITS#221101628 / 220301602 a. Fix: USG FLEX unexpected reboot | V | |
10. | eITS#221201009 a. Fix: SNMP get incorrect value after the interface is disconnected. | V | |
11. | eITS#221000144 a. Fix: CPU and memory usage don't display in Monitor > Firewall > Status. Event log is also empty. | V | |
12. | eITS#221000422 a. Fix: WiFi clients have no internet access due to IPS customized signatures that are created in the previous on-premises mode. | V | |
13. | eITS#221100122 a. Fix: USG FLEX becomes offline on Nebula when the number of Firewall clients exceed 2048. | V | |
14. | eITS#221200797 a. Fix: In the Monitor > Clients > Firewall page only the clients connected to lan1 will be displayed and the clients connected to other ports such as SFP port will not be displayed. | V | |
15. | Common vulnerabilities and Exposures: ZLD5.35 is no longer vulnerable to the following CVE References: CVE-2022-40603 | V | V |
Re: Application specific BWM in Flex 100
Identify the most used one (starting from Zoom, following with Microsoft Teams, Google Meet, Jitsi, Whatsapp, Telegram, Skype, Discord) and adding the most used casting apps (OBS, Streamyard, Streamlabs) could be a gamechanger for the management.

Re: Application specific BWM in Flex 100
You can use WILDCARD FQDN in BWM like *googlevideo.com or *ttvnw.net
Virtual firewall link to USG/Zywall/VPN — Zyxel Community

Re: Nebula i. Hotel scenario
At the present, there is no maintenance page in captive portal when Internet is down.
We'll create a feature request and evaluate carefully about that.
Please follow us to know any enhancements.
Re: Implementation of daily reboot on NR7101
Re: Implementation of daily reboot on NR7101
Re: USG1100: help me to manage my configuration files
James